Software · Intermediate

Kubernetes Foundations

Take a containerized service from Compose to a real Kubernetes cluster: Pods, Deployments, Services, Ingress, configuration, storage, resources, RBAC, network policy and a practised rollback.

About this course

You can build an image and run it with Compose. The next thing most teams ask of you is to run it on Kubernetes — and Kubernetes does not reward guessing. This course puts a single-node cluster inside your own lab machine and has you operate a small service on it from first `kubectl get nodes` to a production handover. **The cluster and the API (lessons 1–2).** You start the control plane yourself, see how the API server, scheduler, kubelet and containerd fit together, and learn to read the cluster instead of guessing at it. You build the status service image, hand it to the cluster's own image store, and run it as a Pod in its own namespace. **Workloads and traffic (lessons 3–4).** You replace the Pod with a three-replica Deployment, roll out a release that turns out to be broken, watch what a rolling update really does when nothing is checking readiness, and roll it back — with a written change record. Then you put a Service and an Ingress in front of it and prove that traffic reaches the replicas. **Configuration and state (lessons 5–6).** Settings move into a ConfigMap and the password into a Secret; you add startup, readiness and liveness probes and watch each one act. Then you run a stateful service as a StatefulSet with a PersistentVolumeClaim, delete its Pod, and prove the data outlived it. **Operating the cluster (lessons 7–8).** Requests, limits and QoS classes; a Pod that cannot be scheduled; a container killed at its memory limit; an autoscaler that only works once it can read metrics. Then least privilege: a read-only ServiceAccount proved with `kubectl auth can-i`, and a default-deny NetworkPolicy with the few flows the namespace actually needs. **Delivery and troubleshooting (lessons 9–10).** Three planted faults to diagnose and repair in place, then Kustomize bases and overlays for two environments, with Helm and GitOps explained. **Final project.** You ship the whole stack for a synthetic logistics company to `rivermill-dev` and `rivermill-prod`, run a release and a rollback, and write the runbook the next person on call will read. Everything runs on your lab machine `linux01`, on a cluster with no internet access, so nothing depends on a cloud account. The course is a learning pathway toward backend development and platform engineering roles; it does not promise employment or any vendor certification.

Content time
15 h 40 min
Lessons
10
Certificate
Yes
on completion
Choose a career path

Lesson 1 is free. Enroll in a career path to access its full courses.

Lesson 1 is a free preview — read it without an account.

Software — the kind of infrastructure this course is practised on

Outline

Lessons

10 lessons · 15 h 40 min
  1. Lesson 1: Your cluster, and the Kubernetes APIFree preview

    Start a real single-node control plane on your own machine, and learn to ask the cluster what it thinks is true.

    1 h 15 min
  2. Lesson 2: Pods, manifests and namespaces

    Build the status service image, hand it to the cluster's own image store, and run it as a Pod you declared in a file.

    1 h 30 min
  3. Lesson 3: Deployments, rolling updates and rollback

    Three replicas that heal themselves, a release that goes wrong on purpose, and a rollback you have written down before you need it.

    1 h 40 min
  4. Lesson 4: Services, endpoints and Ingress

    Give the workload a stable address, see the endpoint list follow readiness, and route a hostname to it through the cluster's ingress controller.

    1 h 25 min
  5. Lesson 5: ConfigMaps, Secrets and probes

    Move settings out of the image, keep the password out of your files, and give Kubernetes three health signals it can act on.

    1 h 40 min
  6. Lesson 6: Storage, StatefulSets and stable identity

    Give a service a volume that outlives its Pod, a name that never changes, and prove both by deleting the Pod.

    1 h 35 min
  7. Lesson 7: Resources, scheduling and autoscaling

    What your workload reserves, what it is allowed to take, what happens at each edge, and how an autoscaler decides anything.

    1 h 50 min
  8. Lesson 8: Namespaces, RBAC and NetworkPolicy

    Give an account exactly the access it needs, prove it, then stop the namespace talking to anything nobody wrote down.

    1 h 35 min
  9. Lesson 9: Troubleshooting workloads

    Three workloads, three different faults, one method — observe, hypothesise, test one thing, fix in place, verify, write it down.

    1 h 40 min
  10. Lesson 10: Environments with Kustomize, and what comes next

    One base, two overlays, two environments that differ only where they should — and an honest map of what this cluster cannot teach you.

    1 h 30 min

Where it leads

Part of these career paths